Software guide

Handle a subject access request step by step

Recognise a subject access request, confirm identity, search your systems, prepare a clear response and meet the legal time limit without panic.

Estimated time: 3–10 hours spread over the response periodUpdated: 28 September 2026

Use this guide when a customer, former employee or anyone else asks what personal data your business holds about them. A request can arrive in any form, including by email, text or verbally, and does not have to mention the law. This is general information; complex or disputed requests may need professional advice.

Step by step

  1. Recognise and log the request

    Record the date received, who asked and what they asked for. The time limit usually starts from receipt. Acknowledge the request promptly and tell the person when to expect a response.

  2. Confirm identity if needed

    If you are not sure who is asking, ask for reasonable proof of identity, but only what is necessary. Do not ask for more than you need to be confident. The clock may pause while you wait for this.

  3. Clarify scope if the request is broad

    If you hold a lot of information, you can ask the person to clarify what they are looking for. You must still make a reasonable and proportionate search. Check current ICO guidance, as the rules were updated by the Data (Use and Access) Act 2025.

  4. Search every relevant system

    Search email, customer records, accounts, messaging apps, shared files and paper files using their name, email address, phone and any reference numbers. Record where you searched so you can show the search was reasonable.

  5. Review and redact

    Collect the data and remove information about other people unless they have agreed or it is reasonable to share. Some limited exemptions may apply. Keep a note of anything withheld and why.

  6. Send a clear response on time

    Respond within one month in most cases; this can be extended for complex requests if you tell the person within the first month. Provide copies of the data plus the supporting information the ICO lists, such as purposes and retention periods, in a secure format.

Ready-to-use checklist

  • Date received logged
  • Acknowledgement sent
  • Identity confirmed proportionately
  • Systems searched and listed
  • Third-party information redacted
  • Exemptions noted with reasons
  • Response sent securely within the deadline
  • Copy of response kept

Practical tips

  • In most cases you cannot charge a fee; check the ICO guidance for the limited exceptions.
  • Keeping data tidy and deleting what you no longer need makes future requests much easier.
  • Use a password-protected file or secure portal rather than plain email for sensitive responses.

Common problems

The request came during a dispute with the person.

You must still respond on the same basis. Keep the response factual and complete, and consider professional advice if legal action is likely.

We hold almost nothing about them.

Still reply within the deadline, confirming what you hold or that you hold nothing, and include the required supporting information.

The request seems unfounded or excessive.

There are limited grounds to refuse or charge a reasonable fee in these cases, but the bar is high. Read the ICO guidance carefully and record your reasons before relying on it.